Many modern cyberattacks do not "break the firewall" first — they steal or abuse identity. Once a valid account is owned, attackers move like legitimate employees: reading email, downloading files, and creating hidden forwarding rules. The firewall sees nothing wrong. ITDR (Identity Threat Detection and Response) monitors identity behavior, detects anomalies, and responds before damage spreads. The trend grows more important with cloud adoption and Zero Trust, which puts identity at the center of security.
1. Identity as the New Perimeter
In hybrid environments, apps span SaaS, cloud, and data centers. Classic network perimeters are not enough. If MFA is weak or a session token is stolen, access to email, storage, and admin consoles opens. ITDR focuses on identity signals: impossible travel logins, privilege spikes, suspicious API-key creation, or bulk access to sensitive data in a short window.
Unlike endpoint antivirus, ITDR watches "who did what" across identity directories and applications. Practical threat-detection references can be complemented by operational guidance from CISA on identity and access.
A real example: a finance account logs in from Jakarta at 9:00 a.m., then "logs in again" from Europe at 9:15 — a classic signal that should trigger automatic alerts and session revocation.
2. Core Components of an ITDR Program
Minimum: telemetry from the IdP (Azure AD/Entra, Okta, etc.), SIEM correlation, response playbooks (lock account, revoke sessions, reset MFA), and regular drills. Prioritize privileged accounts — domain admins, cloud owners, service accounts with broad access.
Combine ITDR with authentication hardening such as passkeys and periodic access reviews. Without identity hygiene, detection only floods analysts with false alerts. Clean up inactive accounts, excessive privileges, and ownerless service accounts before expecting accurate detection.
Also connect it to a cyber resilience program so identity response sits inside ransomware and major-incident playbooks — locking cloud admin accounts is often the first step when active attack is detected.
3. Metrics Worth Reporting
Measure time to detect account abuse, time to revoke sessions, percentage of admin accounts with phishing-resistant MFA, and service accounts without an owner. Avoid KPIs that only count failed-login volume — that rises during brute force but does not show whether a valid account was abused.
Mature ITDR shifts security from "waiting for malware" to active oversight of credentials — the most valuable asset in a digital enterprise. Report monthly trends to the risk committee so identity investment shows results.
4. Threat Signals Often Overlooked
Many organizations focus on failed logins but miss subtle patterns: inbox forwarding rule changes, OAuth consent to unknown apps, hidden mailbox creation, or successful logins from hosting ASNs employees rarely use. Modern ITDR hunts these signals at the application layer, not only authentication.
Train the SOC to distinguish identity alerts from network alerts. Fast response — session revocation in minutes, not hours — often prevents data exfiltration before attackers download large archives. Document each identity incident as an internal case study so detection rules keep improving.
Integrate ITDR with security awareness: employees who report suspicious phishing emails provide early signals before accounts are actually abused.
Need to build ITDR capability and strengthen identity controls? PT. Sumber Solusi Optimal helps with IdP assessment, detection design, and response playbooks. Contact us through our enterprise cybersecurity services.